certpass

CertPass — Privacy Policy

Last updated: 21 July 2026

Certpass Pty Ltd (ACN 697 524 342) (CertPass, we, us or our) respects your privacy. We are committed to protecting Personal Information in accordance with the *Privacy Act 1988* (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), which govern how we collect, use, hold, secure and disclose Personal Information.

This Privacy Policy explains how we handle Personal Information across the CertPass platform, our website at certpass.com.au, and our related services (Service).

The Privacy Act defines Personal Information as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.

An important note about our role: CertPass provides a platform used by Registered Training Organisations (RTOs). RTOs use CertPass to issue digital training certificates to their trainees. Much of the Personal Information about trainees is provided to us by an RTO and is handled by us on that RTO's behalf and on its instructions. Where that is the case, the RTO is responsible for how it collects and manages that information, and this Policy should be read together with the privacy policy of the relevant RTO. Sections of this Policy that refer to information we collect from you directly apply mainly to RTO account holders, website visitors and people who contact us.

1. The kinds of Personal Information we collect

The Personal Information we collect depends on how you interact with us. It may include:

1.1 RTO account holders and Users. Contact and identity details (such as name, business name, role, email address, phone number), your RTO number and organisation details, account credentials and security information, training locations, trainer names and identifiers, and records of your use of the Service.

1.2 Trainees (handled on behalf of RTOs). Where an RTO issues certificates through the Service, we handle information about its trainees, which may include name, contact details (email and phone number), Unique Student Identifier (USI), the units of competency or skills completed, training and issue dates, and the resulting certificate records and wallet passes.

1.3 Verifiers. When an employer, auditor or other person scans a certificate's QR code or opens a verification link, we may collect limited technical information (such as IP address and device information) to operate and secure the verification feature. A verification page displays certificate details recorded by the issuing RTO.

1.4 Website visitors and enquiries. If you visit our website or contact us, we may collect your name, email, phone number, the content of your message, and technical information such as your IP address, device and browser information, and usage statistics.

1.5 Billing information. Where you pay for the Service, billing is handled by our third-party payment provider acting as merchant of record. We generally receive limited billing and transaction details, and do not store full payment card numbers ourselves.

1.6 Prospective customers. For marketing, we may hold business contact details of RTOs, including information obtained from publicly available sources such as training.gov.au.

2. How we collect Personal Information

2.1 Directly from you: when you register for or use the Service, set up your organisation profile, contact us, or respond to a survey or enquiry.

2.2 From RTOs: we receive trainee information from the RTO that is issuing certificates (including via manual entry or CSV import into the Service). We rely on the RTO to have collected that information lawfully and to have any necessary consents.

2.3 From third parties and public sources: for example, we may verify RTO details against public registers such as training.gov.au and the Australian Business Register, and we may collect business contact details from publicly available sources for marketing.

2.4 Through your use of our website: including via cookies and similar technologies as described in section 7.

2.5 If we collect Personal Information about you from someone other than you and it is reasonable to do so, we will, where practicable, take steps to make you aware of the collection — except where an exception under the Privacy Act applies or the collection is required or authorised by law.

3. Why we collect, use and disclose Personal Information

We collect, use and disclose Personal Information for the primary purpose for which it was collected, and for related secondary purposes you would reasonably expect. These purposes include:

(a) providing, operating, maintaining and securing the Service, including account registration, RTO verification, and issuing, delivering and verifying certificates; (b) delivering certificates and wallet passes to trainees by SMS and email on behalf of RTOs; (c) operating verification pages so that certificates can be checked by employers, auditors and others; (d) processing payments and managing billing and accounts; (e) providing customer support and responding to enquiries and complaints; (f) improving, developing and analysing the Service, and maintaining its security and integrity; (g) marketing our products and services to RTOs and prospective customers (see section 6); and (h) complying with our legal obligations and protecting our lawful interests.

3.1 We may also use or disclose Personal Information where required or authorised by law, where necessary to lessen or prevent a serious threat to a person's life, health or safety, or where we reasonably suspect unlawful activity.

4. Who we disclose Personal Information to

We may disclose Personal Information to:

(a) the RTO that issued or is associated with the relevant certificate (and, where you are an RTO, we make trainee records available to you within your account); (b) our service providers and sub-processors who help us operate the Service (see section 5); (c) our professional advisers (such as legal and accounting advisers) where reasonably required; (d) government agencies, regulators or law enforcement where required or authorised by law; and (e) a purchaser or successor in connection with an actual or proposed sale or reorganisation of our business.

5. Our service providers and sub-processors

5.1 We use trusted third-party providers to deliver the Service, including for hosting and infrastructure, database and file storage, authentication, email delivery, SMS delivery, digital wallet pass generation (Apple Wallet and Google Wallet), and payment processing.

5.2 These providers currently include (among others):

We may update this list as our providers change. We take reasonable steps to ensure our providers handle Personal Information consistently with the Privacy Act.

5.3 We only disclose Personal Information to these providers to the extent needed for them to perform their services to us.

6. Direct marketing

6.1 We may use your business contact details to send you information about our products, services and offers that we consider may be of interest to you, by email, SMS or telephone, where you have consented or where it is within your reasonable expectation given your dealings with us.

6.2 You can opt out of marketing at any time using the unsubscribe facility in the relevant message or by contacting us at hello@certpass.com.au. We do not use sensitive information for direct marketing without your consent.

6.3 Certificate delivery messages to trainees (such as the SMS and email containing a wallet pass) are service messages sent on behalf of the issuing RTO, not marketing.

7. Cookies, analytics and IP addresses

7.1 Our website may use cookies and similar technologies to help it function, remember your preferences, understand usage, and improve your experience. Most cookies do not identify you personally.

7.2 You can set your browser to notify you about, or to reject, cookies. If you disable cookies, some parts of our website may not work as intended.

7.3 We may collect IP addresses and technical information to operate, secure and troubleshoot the Service. This information does not usually identify you personally, but where it is combined with other Personal Information we hold, we treat it as Personal Information.

8. Overseas disclosure

8.1 Some of our service providers store or process data outside Australia. This means Personal Information may be disclosed to, stored in, or accessed from countries outside Australia, which currently include the United States (where our infrastructure, database, authentication, email, SMS, payment and wallet providers operate).

8.2 Where we disclose Personal Information overseas, we take steps that are reasonable in the circumstances to ensure recipients handle it consistently with the Australian Privacy Principles. Because we use internet-based services accessible from multiple locations, it is not always practicable to specify every country in which information may be held.

9. Sensitive information

9.1 Sensitive information is a subset of Personal Information (for example health, biometric, or racial or ethnic information). We do not generally seek to collect sensitive information, and will only do so with consent or where required or authorised by law.

9.2 A Unique Student Identifier (USI) is not sensitive information under the Privacy Act, but it is a government-related identifier that we treat with additional care. We use and disclose USIs only as needed to provide the Service on behalf of RTOs, and as permitted by law.

10. How we keep Personal Information secure

10.1 We take reasonable steps to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include encryption in transit and at rest, access controls and tenant isolation, secure authentication (including multi-factor authentication for administrative access), and unguessable certificate identifiers for verification pages.

10.2 No method of transmission or storage is completely secure, and we cannot guarantee absolute security, particularly where human error or malicious third-party activity is involved.

11. How long we keep Personal Information

11.1 We keep Personal Information for as long as needed to provide the Service and for related purposes, and to meet our legal, accounting and record-keeping obligations. Trainee records are retained while the relevant RTO account is active and thereafter in line with our data-retention practices, unless the RTO instructs otherwise or the law requires a different period.

11.2 When Personal Information is no longer needed, we take reasonable steps to destroy or de-identify it, except for copies held in routine backups or that we are required by law to retain.

12. Access to, and correction of, your Personal Information

12.1 You may request access to, or correction of, the Personal Information we hold about you by contacting us at hello@certpass.com.au. We will respond within a reasonable time and may need to verify your identity. In limited circumstances permitted by law we may decline a request, and if so we will explain why.

12.2 If your request relates to trainee information that we hold on behalf of an RTO, we may direct you to, or need to consult with, that RTO, as the RTO is responsible for its own records.

13. Data breaches

13.1 We maintain procedures to identify and respond to data breaches. If a breach involving Personal Information is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches scheme in the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required. Where we handle information on behalf of an RTO, we will also work with that RTO so it can meet its obligations.

14. Anonymity and pseudonymity

14.1 Where lawful and practicable, you may deal with us anonymously or using a pseudonym. However, this is often not practicable — for example, we cannot issue or verify a certificate without the relevant identifying details.

15. Complaints and how to contact us

15.1 If you have a question or complaint about how we have handled your Personal Information, please contact our Privacy Officer:

Certpass Pty Ltd (ACN 697 524 342) Attention: Privacy Officer Email: hello@certpass.com.au Postal address: [insert postal address]

15.2 We will acknowledge your complaint, work with you to understand it, and aim to resolve it within a reasonable time. We will keep you informed of our progress and the basis for any decision.

15.3 If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

16. Changes to this Privacy Policy

16.1 We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We will publish the updated version on our website and update the "last updated" date above. Where appropriate, we will take reasonable steps to notify you of material changes.

16.2 By continuing to use the Service after an updated Policy takes effect, you acknowledge the updated Policy.